PkgRadar

Cargo · crates.io

hk

Remote Payload: matched "github.com/jdx/hk/releases/download"

Why PkgRadar flagged 1.48.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/jdx/hk/releases/download" · hk-1.48.0/src/cli/init/generator.rs
mediumRemote Payloadmatched "github.com/jdx/hk/releases/download" · hk-1.48.0/src/cli/migrate/mod.rs
mediumRemote Payloadmatched "github.com/jdx/hk/releases/download" · hk-1.48.0/src/cli/migrate/pre_commit.rs
mediumRemote Payloadmatched "github.com/jdx/hk/releases/download" · hk-1.48.0/src/config.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.48.0High risk242026-06-11
1.47.0High risk242026-06-09
1.46.0Review242026-05-27

Block this in CI

PkgRadar gates hk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]